// For flags

CVE-2021-37127

 

Severity Score

7.2
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.

Se presenta una vulnerabilidad en la administración de firmas en algunos productos de Huawei. Un atacante puede falsificar la firma y omitir la comprobación de la misma. Durante el proceso de actualización del firmware, una explotación con éxito de esta vulnerabilidad puede causar que el archivo de sistema forjado sobrescriba el archivo de sistema correcto. Las versiones de producto afectadas incluyen: iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300; iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-20 CVE Reserved
  • 2021-10-27 CVE Published
  • 2023-05-19 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-347: Improper Verification of Cryptographic Signature
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00cp2001
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00cp2001"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00cp2002
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00cp2002"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc100
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc100"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc110
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc110"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc120
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc120"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc200
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc200"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc210
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc210"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco 6000 Firmware
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware"
v600r010c00spc300
Search vendor "Huawei" for product "Imanager Neteco 6000 Firmware" and version "v600r010c00spc300"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco 6000
Search vendor "Huawei" for product "Imanager Neteco 6000"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc100
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc100"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc110
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc110"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc120
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc120"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc190
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc190"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc200
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc200"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc201
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc201"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc202
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc202"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe
Huawei
Search vendor "Huawei"
Imanager Neteco Firmware
Search vendor "Huawei" for product "Imanager Neteco Firmware"
v600r009c00spc210
Search vendor "Huawei" for product "Imanager Neteco Firmware" and version "v600r009c00spc210"
-
Affected
in Huawei
Search vendor "Huawei"
Imanager Neteco
Search vendor "Huawei" for product "Imanager Neteco"
--
Safe